logo

How Bug Bounty Uncovered A 5-Year-Old Vulnerability In Hours

ID: 6c05a4d5-048d-5196-ad4d-ff3f76bad2db

STIX ID: report--6c05a4d5-048d-5196-ad4d-ff3f76bad2db

Feed Name: HackerOne Blog

Threat Score
50/100

Date Published: 2024-11-26

Date Updated: 2026-06-11

...
...

After acquiring PullRequest, HackerOne added PullRequest assets to its bug bounty program and within 48 hours a researcher reported a five‑year‑old blind Cross‑Site Scripting (XSS) in a customer rating form that could trigger when employees viewed submissions via archived unique rating links. HackerOne classified the issue as high severity (8.8/10), removed the unused vulnerable code, tightened Content Security Policy, began migrating legacy code to React, added expiration to rating links, and confirmed remediation via a retest with no evidence of prior exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.